Bug #74888 [NEW]: Timeout never or randomly reached for TLS sockets
| From: | mmn at hethane dot se | Date: | Sun, 09 Jul 2017 21:21:01 +0000 |
| Subject: | Bug #74888 [NEW]: Timeout never or randomly reached for TLS sockets | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-209947@lists.php.net to get a copy of this message | ||
From: mmn at hethane dot se
Operating system: Ubuntu 16.04
PHP version: 7.2.0alpha3
Package: Streams related
Bug Type: Bug
Bug description:Timeout never or randomly reached for TLS sockets
Description:
------------
Hello I am using the PEAR HTTP_Request2 library in the software GNU
social to make remote requests. I have noticed recently a "malicious"
remote server in our federated network that simply replies _extremely_
slowly_ it seems.
This causes our background processes - which run in PHP - to stall
whenever connecting to these remote servers. For this reason, PHP has
the default_socket_timeout=60, which should cause connections to die
relatively quickly (at least with double that specified timeout in
seconds, according to bug #48280 at least).
However, this does not seem to happen. The server in this case manages
to keep alive connections with socket timeout of 2 seconds for much
longer than that. I don't know if it is related to the timeout value -
but it does _seem_ to be proportionate to the configured timeout (2
second timeouts die faster than 10 second timeouts etc.).
With HTTP_Request2 this _only_ happens with the Socket adapter and not
the Curl adapter (which flawlessly hits the timeout on the millisecond)
which leads me to believe it's the underlying PHP sockets that have an
issue here.
I'm thinking it could be related to bug #41631 that seems to have been a
long-living issue with TLS connections not respecting the socket
timeout? This has so far only been experienced in HTTPS connections in
GNU social at least.
The below test script uses HTTP_Request2 as mentioned,
https://pear.php.net/package/HTTP_Request2
(maybe requires some other
PEAR stuff too)
Test script:
---------------
require('HTTP/Request2.php');
$r = new HTTP_Request2();
$r->setConfig(['connect_timeout'=>1, 'timeout'=>2]);
$r->setMethod($r::METHOD_POST);
foreach(['Thanks-For-Debugging: Really like it.'] as $header) {
$r->setHeader($header); }
$r->setUrl('https://hash.my/api/subscriptions/1234');
$time=time(); echo "$time\n"; try {$r->send();} catch(Exception $e){echo
get_class($e).': '.$e->getMessage();} echo "\nIt actually took:
".(time()-$time)." seconds\n";
Expected result:
----------------
HTTP_Request2_MessageException: Request timed out after 2 second(s)
It actually took: 2 seconds
Actual result:
--------------
HTTP_Request2_MessageException: Request timed out after 2 second(s)
It actually took: 48 seconds
(Note that the value where it says "after n second(s)" is just
HTTP_Request2 reporting it like that because it was my configured,
desired, value.)
--
Edit bug report at https://bugs.php.net/bug.php?id=74888&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74888&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74888&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74888&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=74888&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=74888&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=74888&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=74888&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=74888&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=74888&r=support
Expected behavior: https://bugs.php.net/fix.php?id=74888&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=74888&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=74888&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=74888&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74888&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=74888&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=74888&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=74888&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74888&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=74888&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=74888&r=mysqlcfg